Jump to content

malwarebytes and gmer rootkill shuts down on scan


Recommended Posts

.

DDS (Ver_2011-06-23.01) - NTFSx86 NETWORK

Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_22

Run by Administrator at 13:37:55 on 2011-07-29

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.744 [GMT -5:00]

.

.

============== Running Processes ===============

.

"\\.\globalroot\Device\svchost.exe\svchost.exe"

C:\WINDOWS\system32\svchost -k DcomLaunch

svchost.exe

C:\WINDOWS\System32\svchost.exe -k netsvcs

svchost.exe

svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Mozilla Firefox\firefox.exe

.

============== Pseudo HJT Report ===============

.

uStart Page = hxxp://www.idatalink.com/update

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll

BHO: {243b17de-77c7-46bf-b94b-0b5f309a0e64} - c:\program files\microsoft money\system\mnyside.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll

BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

BHO: {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No File

EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File

uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe

mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\apcups~1.lnk - c:\program files\apc\apc powerchute personal edition\Display.exe

IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe

IE: {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - {DD6687B5-CB43-4211-BFC9-2942CCBDCB3E} - c:\program files\microsoft money\system\mnyside.dll

LSP: mswsock.dll

DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab

DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab

DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1305211315359

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab

TCP: DhcpNameServer = 68.94.156.1 68.94.157.1

TCP: Interfaces\{D0466C97-8798-4A05-9CA6-20B53E58CEEE} : DhcpNameServer = 68.94.156.1 68.94.157.1

Handler: intu-help-qb4 - {ACE22922-D07C-4860-B51B-8CF472FEC2CB} - c:\program files\intuit\quickbooks 2011\HelpAsyncPluggableProtocol.dll

Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - c:\windows\system32\mscoree.dll

Notify: igfxcui - igfxsrvc.dll

.

================= FIREFOX ===================

.

FF - ProfilePath - c:\documents and settings\administrator\application data\mozilla\firefox\profiles\m1npwbof.default\

FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll

.

============= SERVICES / DRIVERS ===============

.

S2 QBVSS;QBIDPService;c:\program files\common files\intuit\dataprotect\QBIDPService.exe [2011-3-5 1257760]

.

=============== Created Last 30 ================

.

2011-07-29 18:20:30 -------- d--h--w- c:\windows\PIF

.

==================== Find3M ====================

.

2011-07-07 00:52:42 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2011-07-07 00:52:42 22712 ----a-w- c:\windows\system32\drivers\mbam.sys

2011-06-02 14:02:05 1858944 ----a-w- c:\windows\system32\win32k.sys

2011-05-19 19:03:46 73728 ----a-w- c:\windows\system32\javacpl.cpl

2011-05-19 19:03:46 472808 ----a-w- c:\windows\system32\deployJava1.dll

2011-05-16 15:54:50 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2011-05-02 15:31:52 692736 ----a-w- c:\windows\system32\inetcomm.dll

.

============= FINISH: 13:38:37.43 ===============

attach.zip

Link to post
Share on other sites

Hello audioman7 and welcome to Malwarebytes! :welcome:

I am D-FRED-BROWN and I will be helping you. :)

Please print or save this topic: it will make it easier for you to follow the instructions and complete all of the necessary steps.

-------------

Please download maxhandle.exe by noahdfear to your desktop

  • Double click and run the application
  • An active internet connection is required so that maxhandle.exe may download a tool from SysInternals (every time it is run).
  • Log is saved to c:\maxhandle.txt
  • If Max++ is not found Nothing found! is echoed to the screen - no log is produced.

Please post the results for my review

-------------

XP

You must first verify that you can logon to the Windows Recovery Console.

To do so, you must have the Recovery Console installed or use the Windows XP installation cd.

How to install and use the Windows XP Recovery Console

Now, go back to Normal Mode.

Next, please download maxlook, saving the file to your desktop.

Double click maxlook.exe to run it. Note - you must run it only once!

As instructed when the tool runs, restart the computer and logon to the Recovery Console.

Execute the following bolded command at the x:\windows> prompt <--- the red x represents your operating system drive letter, usually C

batch look.bat

lookXP.gif

You will see 1 file copied many times then return to the x:\windows> prompt.

Type Exit to restart your computer then logon in normal mode.

Please run maxlook.exe again now. Note - you must run it only once!

It will produce looklog.txt on the desktop and open it.

Please post the results here.

-------------

Please download to your Desktop:

  • TDSSKiller.zip from here and extract it (right click on it => "Extract here").

>>> TDSSKiller: Double-click on TDSSKiller.exe to run the application.

  • Click on the Start Scan button and wait for the scan and disinfection process to be over.
  • If an infected file is detected, the default action will be Cure, click on Continue tdsskiller2.png
  • If a suspicious file is detected, the default action will be Skip, click on Continue tdsskiller3.png
  • If you are asked to reboot the computer to complete the process, click on the Reboot Now button. A report will be automatically saved at the root of the System drive ((usually C:\) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt" (for example, C:\TDSSKiller.2.2.0_20.12.2009_15.31.43_log.txt). Please copy and paste the contents of that file here.
  • If no reboot is required, click on Report. A log file will appear. Please copy and paste the contents of that file in your next reply.

In your next reply, please include the following (you may need to use two posts to get it all in):

  • TDSSKiller_log.txt
how the PC is running now?
-------------
Please download ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
***IMPORTANT: save ComboFix to your Desktop***
* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
Please go here to see a list of programs that should be disabled.
**Note: Do not mouseclick ComboFix's window while it's running. That may cause it to stall**
Please include the C:\ComboFix.txt in your next reply for further review.
Also, please let me know if any problems still remain.
-------------
In your next reply, please include:
  • Maxhandle log (if one is created)
  • Maxlook looklog.txt
  • TDSSKiller log
  • C:\ComboFix.txt

How is your computer running now?

Link to post
Share on other sites

here are the files you asked for. And thank you for helping me! Hopefully that will help clear some things up. Computer was running real slow couldn't search internet at all with out ads popping up in new tabs. I'm trying to use this computer as little as possible. Please inform me of next step P.S. combofix said I had rootkill.zeroaccess

maxhandle.zip

Link to post
Share on other sites

We have some more work to do ;)

Please download SystemLook from one of the links below and save it to your Desktop.

Download Mirror #1

Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:

    :filefind
    mrxsmb.sys


  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.

Note: The log can also be found at on your Desktop entitled SystemLook.txt

Link to post
Share on other sites

here you go...

SystemLook 30.07.11 by jpshortstuff

Log created at 11:40 on 01/08/2011 by Administrator

Administrator - Elevation successful

========== filefind ==========

Searching for "mrxsmb.sys"

C:\WINDOWS\$hf_mig$\KB2511455\SP3QFE\mrxsmb.sys --a---- 457472 bytes [18:17 12/05/2011] [13:19 17/02/2011] FB7DFD15D760AD339837A470F0E780D3

C:\WINDOWS\$hf_mig$\KB2536276\SP3QFE\mrxsmb.sys --a---- 457856 bytes [07:11 16/06/2011] [16:47 29/04/2011] 8DD801E28EB76FDA2A38907882A0036F

C:\WINDOWS\$hf_mig$\KB980232\SP2QFE\mrxsmb.sys --a---- 457216 bytes [16:08 12/05/2011] [12:48 24/02/2010] 3500E756812E716351F2D341AE1D5623

C:\WINDOWS\$hf_mig$\KB980232\SP3GDR\mrxsmb.sys --a---- 455680 bytes [16:08 12/05/2011] [13:11 24/02/2010] F3AEFB11ABC521122B67095044169E98

C:\WINDOWS\$hf_mig$\KB980232\SP3QFE\mrxsmb.sys --a---- 457216 bytes [16:08 12/05/2011] [11:57 24/02/2010] D09B9F0B9960DD41E73127B7814C115F

C:\WINDOWS\$NtServicePackUninstall$\mrxsmb.sys -----c- 454016 bytes [17:26 12/05/2011] [12:31 24/02/2010] FB6C89BB3CE282B08BDB1E3C179E1C39

C:\WINDOWS\$NtUninstallKB2511455$\mrxsmb.sys -----c- 455680 bytes [18:49 12/05/2011] [13:11 24/02/2010] F3AEFB11ABC521122B67095044169E98

C:\WINDOWS\$NtUninstallKB2536276$\mrxsmb.sys -----c- 455936 bytes [14:12 26/07/2011] [13:18 17/02/2011] 0EA4D8ED179B75F8AFA7998BA22285CA

C:\WINDOWS\$NtUninstallKB980232$\mrxsmb.sys -----c- 456576 bytes [17:47 12/05/2011] [19:17 13/04/2008] 68755F0FF16070178B54674FE5B847B0

C:\WINDOWS\$NtUninstallKB980232_0$\mrxsmb.sys -----c- 451456 bytes [16:33 12/05/2011] [06:15 04/08/2004] 1FD607FC67F7F7C633C3DA65BFC53D18

C:\WINDOWS\Driver Cache\i386\mrxsmb.sys ------- 456320 bytes [16:08 12/05/2011] [16:19 29/04/2011] 0DC719E9B15E902346E87E9DCD5751FA

C:\WINDOWS\maxdrive\mrxsmb.sys --a---- 456320 bytes [13:00 03/09/2002] [16:19 29/04/2011] 2E53DF7B36FFF7B3CD9986A4D176AEF8

C:\WINDOWS\ServicePackFiles\i386\mrxsmb.sys ------- 456576 bytes [06:15 04/08/2004] [19:17 13/04/2008] 68755F0FF16070178B54674FE5B847B0

C:\WINDOWS\SoftwareDistribution\Download\7662ce4d10dbc4afae84f95151b83183\SP3GDR\mrxsmb.sys --a---- 456320 bytes [07:11 16/06/2011] [16:19 29/04/2011] 0DC719E9B15E902346E87E9DCD5751FA

C:\WINDOWS\SoftwareDistribution\Download\7662ce4d10dbc4afae84f95151b83183\SP3QFE\mrxsmb.sys --a---- 457856 bytes [07:11 16/06/2011] [16:47 29/04/2011] 8DD801E28EB76FDA2A38907882A0036F

C:\WINDOWS\system32\dllcache\mrxsmb.sys -----c- 456320 bytes [16:08 12/05/2011] [16:19 29/04/2011] 0DC719E9B15E902346E87E9DCD5751FA

C:\WINDOWS\system32\drivers\mrxsmb.sys --a---- 456320 bytes [13:00 03/09/2002] [16:19 29/04/2011] 2E53DF7B36FFF7B3CD9986A4D176AEF8

-= EOF =-

Link to post
Share on other sites

Please do the following:

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

KILLALL::

Fcopy::

C:\WINDOWS\system32\dllcache\mrxsmb.sys | C:\WINDOWS\system32\drivers\mrxsmb.sys

Reglock::

[HKEY_USERS\S-1-5-21-448539723-1085031214-839522115-500\Software\Microsoft\Internet Explorer\User Preferences]

Reboot::

Save this as CFScript.txt, in the same location as ComboFix.exe

CFScriptB-4.gif

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I shall require in your next reply.

Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

Please include the newly-created C:\ComboFix.txt in your next reply, and let me know how things are running now ;)

Link to post
Share on other sites

ran first time and stalled.. recreated file and ran the second time no problem here is log

ComboFix 11-08-01.02 - Administrator 08/01/2011 13:08:56.2.1 - x86

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.687 [GMT -5:00]

Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe

Command switches used :: c:\documents and settings\Administrator\Desktop\CFScript.txt

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

.

--------------- FCopy ---------------

.

c:\windows\system32\dllcache\mrxsmb.sys --> c:\windows\system32\drivers\mrxsmb.sys

.

((((((((((((((((((((((((( Files Created from 2011-07-01 to 2011-08-01 )))))))))))))))))))))))))))))))

.

.

2011-08-01 14:09 . 2011-08-01 14:16 -------- d-----w- c:\windows\maxdrive

2011-08-01 13:47 . 2011-07-07 18:28 520496 ----a-w- c:\windows\Listdlls.exe

2011-08-01 13:47 . 2011-05-17 17:48 423288 ----a-w- c:\windows\handle.exe

2011-07-29 18:20 . 2011-07-29 18:20 -------- d--h--w- c:\windows\PIF

2011-07-27 21:41 . 2011-07-27 21:41 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2011-08-01 14:53 . 2011-08-01 14:53 11083 ----a-w- C:\maxhandle.zip

2011-07-07 00:52 . 2011-06-01 21:11 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2011-07-07 00:52 . 2011-06-01 21:11 22712 ----a-w- c:\windows\system32\drivers\mbam.sys

2011-06-02 14:02 . 2002-09-03 13:00 1858944 ----a-w- c:\windows\system32\win32k.sys

2011-05-19 19:03 . 2011-05-19 19:03 73728 ----a-w- c:\windows\system32\javacpl.cpl

2011-05-19 19:03 . 2011-05-19 19:03 472808 ----a-w- c:\windows\system32\deployJava1.dll

2011-05-16 15:54 . 2011-05-16 15:54 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2011-05-12 01:04 . 2011-05-12 01:04 459944 ----a-w- c:\windows\system32\drivers\smwdm.sys

2011-05-12 01:04 . 2011-05-12 01:04 3744 ----a-w- c:\windows\system32\drivers\smsens.sys

2011-05-12 01:04 . 2011-05-12 01:04 2619 ----a-w- c:\windows\system32\drivers\sensupgd.sys

2011-05-12 01:04 . 2011-05-12 01:04 720896 ----a-w- c:\windows\system32\a3d.dll

2011-05-12 01:04 . 2011-05-12 01:04 53248 ----a-w- c:\windows\system32\Prounstl.exe

2011-05-12 01:04 . 2011-05-12 01:04 23040 ----a-w- c:\windows\system32\IntelNic.dll

2011-05-12 01:04 . 2011-05-12 01:04 139776 ----a-w- c:\windows\system32\drivers\e100b325.sys

2011-05-12 01:04 . 2011-05-12 01:04 26679 ----a-w- c:\windows\system32\drivers\wa301b.sys

2011-05-12 01:04 . 2011-05-12 01:04 315392 ----a-w- c:\windows\system32\igfxsrvc.dll

2011-05-12 01:04 . 2011-05-12 01:04 26679 ----a-w- c:\windows\system32\drivers\wa301a.sys

2011-05-12 01:04 . 2011-05-12 01:04 159744 ----a-w- c:\windows\system32\igfxrptg.lrc

2011-05-12 01:04 . 2011-05-12 01:04 155648 ----a-w- c:\windows\system32\igfxtray.exe

2011-05-12 01:04 . 2011-05-12 01:04 155648 ----a-w- c:\windows\system32\igfxrtrk.lrc

2011-05-12 01:04 . 2011-05-12 01:04 155648 ----a-w- c:\windows\system32\igfxrtha.lrc

2011-05-12 01:04 . 2011-05-12 01:04 155648 ----a-w- c:\windows\system32\igfxrsve.lrc

2011-05-12 01:04 . 2011-05-12 01:04 155648 ----a-w- c:\windows\system32\igfxrrus.lrc

2011-05-12 01:04 . 2011-05-12 01:04 159744 ----a-w- c:\windows\system32\igfxrptb.lrc

2011-05-12 01:04 . 2011-05-12 01:04 159744 ----a-w- c:\windows\system32\igfxrplk.lrc

2011-05-12 01:04 . 2011-05-12 01:04 159744 ----a-w- c:\windows\system32\igfxrnld.lrc

2011-05-12 01:04 . 2011-05-12 01:04 159744 ----a-w- c:\windows\system32\igfxrita.lrc

2011-05-12 01:04 . 2011-05-12 01:04 159744 ----a-w- c:\windows\system32\igfxrhun.lrc

2011-05-12 01:04 . 2011-05-12 01:04 159744 ----a-w- c:\windows\system32\igfxrfrc.lrc

2011-05-12 01:04 . 2011-05-12 01:04 159744 ----a-w- c:\windows\system32\igfxrfra.lrc

2011-05-12 01:04 . 2011-05-12 01:04 155648 ----a-w- c:\windows\system32\igfxrnor.lrc

2011-05-12 01:04 . 2011-05-12 01:04 151552 ----a-w- c:\windows\system32\igfxrkor.lrc

2011-05-12 01:04 . 2011-05-12 01:04 151552 ----a-w- c:\windows\system32\igfxrjpn.lrc

2011-05-12 01:04 . 2011-05-12 01:04 151552 ----a-w- c:\windows\system32\igfxrheb.lrc

2011-05-12 01:04 . 2011-05-12 01:04 155648 ----a-w- c:\windows\system32\igfxrfin.lrc

2011-05-12 01:04 . 2011-05-12 01:13 151552 ----a-w- c:\windows\system32\igfxres.dll

2011-05-12 01:04 . 2011-05-12 01:04 503808 ----a-w- c:\windows\system32\igfxress.dll

2011-05-12 01:04 . 2011-05-12 01:04 163840 ----a-w- c:\windows\system32\igfxrell.lrc

2011-05-12 01:04 . 2011-05-12 01:04 159744 ----a-w- c:\windows\system32\igfxresp.lrc

2011-05-12 01:04 . 2011-05-12 01:04 155648 ----a-w- c:\windows\system32\igfxreng.lrc

2011-05-12 01:04 . 2011-05-12 01:04 155648 ----a-w- c:\windows\system32\igfxrdeu.lrc

2011-05-12 01:04 . 2011-05-12 01:04 155648 ----a-w- c:\windows\system32\igfxrdan.lrc

2011-05-12 01:04 . 2011-05-12 01:04 155648 ----a-w- c:\windows\system32\igfxrcsy.lrc

2011-05-12 01:04 . 2011-05-12 01:04 151552 ----a-w- c:\windows\system32\igfxrenu.lrc

2011-05-12 01:04 . 2011-05-12 01:04 151552 ----a-w- c:\windows\system32\igfxrcht.lrc

2011-05-12 01:04 . 2011-05-12 01:04 204800 ----a-w- c:\windows\system32\igfxpph.dll

2011-05-12 01:04 . 2011-05-12 01:04 151552 ----a-w- c:\windows\system32\igfxrchs.lrc

2011-05-12 01:04 . 2011-05-12 01:04 151552 ----a-w- c:\windows\system32\igfxrarb.lrc

2011-05-12 01:04 . 2011-05-12 01:04 151552 ----a-w- c:\windows\system32\igfxrara.lrc

2011-05-12 01:04 . 2011-05-12 01:04 118784 ----a-w- c:\windows\system32\igfxhk.dll

2011-05-12 01:04 . 2011-05-12 01:04 94208 ----a-w- c:\windows\system32\igfxcpl.cpl

2011-05-12 01:04 . 2011-05-12 01:04 91678 ----a-w- c:\windows\system32\drivers\ialmsbw.sys

2011-05-12 01:04 . 2011-05-12 01:04 86016 ----a-w- c:\windows\system32\igfxdo.dll

2011-05-12 01:04 . 2011-05-12 01:04 79323 ----a-w- c:\windows\system32\drivers\ialmnt5.sys

2011-05-12 01:04 . 2011-05-12 01:04 71514 ----a-w- c:\windows\system32\drivers\ialmkchw.sys

2011-05-12 01:04 . 2011-05-12 01:04 495616 ----a-w- c:\windows\system32\igfxcfg.exe

2011-05-12 01:04 . 2011-05-12 01:04 45056 ----a-w- c:\windows\system32\igfxdgps.dll

2011-05-12 01:04 . 2011-05-12 01:04 34367 ----a-w- c:\windows\system32\ialmrnt5.dll

2011-05-12 01:04 . 2011-05-12 01:04 221184 ----a-w- c:\windows\system32\igfxeud.dll

2011-05-12 01:04 . 2011-05-12 01:04 151552 ----a-w- c:\windows\system32\igfxdiag.exe

2011-05-12 01:04 . 2011-05-12 01:04 147456 ----a-w- c:\windows\system32\igfxdev.dll

2011-05-12 01:04 . 2011-05-12 01:04 1859584 ----a-w- c:\windows\system32\ialmgicd.dll

2011-05-12 01:04 . 2011-05-12 01:04 86073 ----a-w- c:\windows\system32\iAlmCoIn_0_v6.dll

2011-05-12 01:04 . 2011-05-12 01:04 77372 ----a-w- c:\windows\system32\ialmdnt5.dll

2011-05-12 01:04 . 2011-05-12 01:04 533570 ----a-w- c:\windows\system32\ialmdd5.dll

2011-05-12 01:04 . 2011-05-12 01:04 30263 ----a-w- c:\windows\system32\drivers\a311.sys

2011-05-12 01:04 . 2011-05-12 01:04 184320 ----a-w- c:\windows\system32\ialmgdev.dll

2011-05-12 01:04 . 2011-05-12 01:04 163067 ----a-w- c:\windows\system32\ialmdev5.dll

2011-05-12 01:04 . 2011-05-12 01:04 114688 ----a-w- c:\windows\system32\hkcmd.exe

2011-05-12 01:04 . 2011-05-12 01:04 114688 ----a-w- c:\windows\system32\hccutils.dll

2011-05-12 01:04 . 2011-05-12 01:04 10295 ----a-w- c:\windows\system32\drivers\a312.sys

2011-05-12 01:04 . 2011-05-12 01:04 32823 ----a-w- c:\windows\system32\drivers\a310.sys

2011-05-12 01:04 . 2011-05-12 01:04 26167 ----a-w- c:\windows\system32\drivers\a303.sys

2011-05-12 01:04 . 2011-05-12 01:04 25655 ----a-w- c:\windows\system32\drivers\a304.sys

2011-05-12 01:04 . 2011-05-12 01:04 25143 ----a-w- c:\windows\system32\drivers\a309.sys

2011-05-12 01:04 . 2011-05-12 01:04 20023 ----a-w- c:\windows\system32\drivers\a307.sys

2011-05-12 01:04 . 2011-05-12 01:04 20021 ----a-w- c:\windows\system32\drivers\vch.sys

2011-05-12 01:04 . 2011-05-12 01:04 15927 ----a-w- c:\windows\system32\drivers\a306.sys

2011-05-12 01:04 . 2011-05-12 01:04 11319 ----a-w- c:\windows\system32\drivers\a305.sys

2011-05-12 01:04 . 2011-05-12 01:04 10295 ----a-w- c:\windows\system32\drivers\a308.sys

2011-05-12 01:04 . 2011-05-12 01:04 10295 ----a-w- c:\windows\system32\drivers\a302.sys

2011-06-25 16:01 . 2011-05-12 20:19 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll

.

.

((((((((((((((((((((((((((((( SnapShot@2011-08-01_14.42.09 )))))))))))))))))))))))))))))))))))))))))

.

+ 2011-08-01 18:15 . 2011-08-01 18:15 16384 c:\windows\temp\Perflib_Perfdata_a4.dat

+ 2002-09-03 13:00 . 2011-04-29 16:19 456320 c:\windows\system32\dllcache\mrxsmb.sys

- 2011-05-12 16:08 . 2011-04-29 16:19 456320 c:\windows\system32\dllcache\mrxsmb.sys

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-07-07 449584]

.

c:\documents and settings\All Users\Start Menu\Programs\Startup\

APC UPS Status.lnk - c:\program files\APC\APC PowerChute Personal Edition\Display.exe [2011-5-12 221247]

.

[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^OpenOffice.org 3.3.lnk]

path=c:\documents and settings\Administrator\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk

backup=c:\windows\pss\OpenOffice.org 3.3.lnkStartup

.

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Intuit Data Protect.lnk]

path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Intuit Data Protect.lnk

backup=c:\windows\pss\Intuit Data Protect.lnkCommon Startup

.

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]

path=c:\documents and settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk

backup=c:\windows\pss\QuickBooks Update Agent.lnkCommon Startup

.

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks_Standard_21.lnk]

path=c:\documents and settings\All Users\Start Menu\Programs\Startup\QuickBooks_Standard_21.lnk

backup=c:\windows\pss\QuickBooks_Standard_21.lnkCommon Startup

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]

2011-03-30 17:29 937920 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]

2011-01-30 15:45 35736 ----a-w- c:\program files\Adobe\Reader 10.0\Reader\reader_sl.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]

2008-04-14 00:12 15360 ----a-w- c:\windows\system32\ctfmon.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]

2011-05-12 01:04 114688 ----a-w- c:\windows\system32\hkcmd.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]

2011-05-12 01:04 155648 ----a-w- c:\windows\system32\igfxtray.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Intuit SyncManager]

2011-02-22 08:28 1497352 ----a-w- c:\program files\Common Files\Intuit\Sync\IntuitSyncManager.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]

2011-07-07 00:52 449584 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent]

2002-07-17 16:00 200767 ----a-w- c:\program files\Microsoft Money\System\mnyexpr.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PROMon.exe]

2002-04-18 23:32 73728 ----a-w- c:\windows\system32\PROMon.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]

2010-05-14 16:44 248552 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Program Files\\Intuit\\QuickBooks 2011\\QBDBMgrN.exe"=

.

R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [6/1/2011 4:11 PM 366640]

R2 QBVSS;QBIDPService;c:\program files\Common Files\Intuit\DataProtect\QBIDPService.exe [3/5/2011 9:03 PM 1257760]

R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [6/1/2011 4:11 PM 22712]

.

--- Other Services/Drivers In Memory ---

.

*NewlyCreated* - NMSCFG

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.idatalink.com/update

TCP: DhcpNameServer = 68.94.156.1 68.94.157.1

DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab

DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab

FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\m1npwbof.default\

.

.

**************************************************************************

.

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2011-08-01 13:15

Windows 5.1.2600 Service Pack 3 NTFS

.

scanning hidden processes ...

.

scanning hidden autostart entries ...

.

scanning hidden files ...

.

scan completed successfully

hidden files: 0

.

**************************************************************************

.

--------------------- DLLs Loaded Under Running Processes ---------------------

.

- - - - - - - > 'explorer.exe'(3436)

c:\windows\system32\WININET.dll

c:\windows\system32\ieframe.dll

c:\windows\system32\webcheck.dll

.

------------------------ Other Running Processes ------------------------

.

c:\program files\APC\APC PowerChute Personal Edition\mainserv.exe

c:\program files\Java\jre6\bin\jqs.exe

c:\windows\System32\NMSSvc.exe

c:\program files\Common Files\Lanovation\PrismXL\PRISMXL.SYS

c:\program files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe

c:\windows\system32\wscntfy.exe

c:\program files\APC\APC PowerChute Personal Edition\apcsystray.exe

.

**************************************************************************

.

Completion time: 2011-08-01 13:19:38 - machine was rebooted

ComboFix-quarantined-files.txt 2011-08-01 18:19

ComboFix2.txt 2011-08-01 14:46

.

Pre-Run: 20,535,885,824 bytes free

Post-Run: 20,525,596,672 bytes free

.

- - End Of File - - 498D107FF48186DB28DB43B127F24474

Link to post
Share on other sites

Glad to hear things are better! :)

Before we move on, let's run the following online scans to make sure there's nothing hiding that we may have missed:

Please run a free online scan with the ESET Online Scanner

Note: You will need to use Internet Explorer for this scan.

  1. Tick the box next to YES, I accept the Terms of Use.
  2. Click Start
  3. When asked, allow the ActiveX control to install
  4. Click Start
  5. Make sure that the options Remove found threats is Unchecked and the option Scan unwanted applications is checked
  6. Click Scan
    Wait for the scan to finish
  7. Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  8. Copy and paste that log as a reply to this topic

--------

Please use the Internet Explorer and run a BitDefender Online scan from Here

  • Please check I agree with the Terms and Conditions and click Start Here
  • You will need to allow an Active X install for the scan to run.
  • Leave the scanning options at default and click Start Scan

Please post the results in your next reply.

Link to post
Share on other sites

sorry they took a while large harddrives

QuickScan Beta 32-bit v0.9.9.99

-------------------------------

Scan date: Mon Aug 01 16:22:43 2011

Machine ID: 8019C09A

No infection found.

-------------------

Processes

---------

APC PowerChute Personal Edition 2480 C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe

APC PowerChute Personal Edition 132 C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe

Java Platform SE 6 U22 164 C:\Program Files\Java\jre6\bin\jqs.exe

Malwarebytes' Anti-Malware 1716 C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe

Malwarebytes' Anti-Malware 228 C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

Microsoft® Windows® Operating System 1400 C:\WINDOWS\system32\spoolsv.exe

Microsoft® Windows® Operating System 1800 C:\WINDOWS\system32\wscntfy.exe

Microsoft® Works 7.0 3936 C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe

NMS 340 C:\WINDOWS\system32\NMSSvc.Exe

PrismXL Software Family 444 C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS

QBIDPService 920 C:\Program Files\Common Files\Intuit\DataProtect\QBIDPService.exe

QuickBooks 644 C:\Program Files\Intuit\QuickBooks 2011\QBW32.EXE

QuickBooks for Windows 504 C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe

(verified) Microsoft® .NET Framework 2388 C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe

(verified) Microsoft® Windows® Operating System 3436 C:\WINDOWS\explorer.exe

(verified) Microsoft® Windows® Operating System 2088 C:\WINDOWS\system32\alg.exe

(verified) Microsoft® Windows® Operating System 648 C:\WINDOWS\system32\csrss.exe

(verified) Microsoft® Windows® Operating System 2156 C:\WINDOWS\system32\ctfmon.exe

(verified) Microsoft® Windows® Operating System 728 C:\WINDOWS\system32\lsass.exe

(verified) Microsoft® Windows® Operating System 716 C:\WINDOWS\system32\services.exe

(verified) Microsoft® Windows® Operating System 384 C:\WINDOWS\system32\smss.exe

(verified) Microsoft® Windows® Operating System 888 C:\WINDOWS\system32\svchost.exe

(verified) Microsoft® Windows® Operating System 964 C:\WINDOWS\system32\svchost.exe

(verified) Microsoft® Windows® Operating System 1060 C:\WINDOWS\system32\svchost.exe

(verified) Microsoft® Windows® Operating System 1108 C:\WINDOWS\system32\svchost.exe

(verified) Microsoft® Windows® Operating System 1260 C:\WINDOWS\system32\svchost.exe

(verified) Microsoft® Windows® Operating System 2016 C:\WINDOWS\system32\svchost.exe

(verified) Microsoft® Windows® Operating System 672 C:\WINDOWS\system32\winlogon.exe

(verified) Microsoft® Windows® Operating System 2912 C:\WINDOWS\system32\wuauclt.exe

(verified) Windows® Internet Explorer 2068 C:\Program Files\Internet Explorer\iexplore.exe

(verified) Windows® Internet Explorer 2328 C:\Program Files\Internet Explorer\iexplore.exe

Network activity

----------------

Process iexplore.exe (2068) connected on port 80 (HTTP) --> 74.125.225.38

Process iexplore.exe (2068) connected on port 80 (HTTP) --> 69.171.224.39

Process iexplore.exe (2068) connected on port 80 (HTTP) --> 198.173.20.112

Process iexplore.exe (2068) connected on port 80 (HTTP) --> 198.173.20.123

Process QBCFMonitorService.exe (504) listens on ports: 8019

Process svchost.exe (964) listens on ports: 135 (RPC)

Autoruns and critical files

---------------------------

Intel® Common User Interface C:\WINDOWS\system32\igfxsrvc.dll

Malwarebytes' Anti-Malware C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe

Microsoft® Windows® Operating System C:\WINDOWS\system32\BROWSEUI.dll

Microsoft® Windows® Operating System C:\WINDOWS\system32\CRYPT32.dll

Microsoft® Windows® Operating System C:\WINDOWS\system32\cryptnet.dll

Microsoft® Windows® Operating System C:\WINDOWS\system32\cscdll.dll

Microsoft® Windows® Operating System C:\WINDOWS\System32\dimsntfy.dll

Microsoft® Windows® Operating System C:\WINDOWS\System32\logon.scr

Microsoft® Windows® Operating System C:\WINDOWS\system32\SHELL32.dll

Microsoft® Windows® Operating System c:\windows\system32\userinit.exe

Microsoft® Windows® Operating System C:\WINDOWS\system32\WlNotify.dll

(verified) Microsoft Genuine Advantage C:\WINDOWS\system32\WgaLogon.dll

(verified) Microsoft® Windows® Operating System C:\WINDOWS\system32\ctfmon.exe

(verified) Microsoft® Windows® Operating System C:\WINDOWS\system32\logonui.exe

(verified) Microsoft® Windows® Operating System C:\WINDOWS\system32\sclgntfy.dll

(verified) Microsoft® Windows® Operating System C:\WINDOWS\system32\stobject.dll

(verified) Windows® Internet Explorer C:\WINDOWS\system32\webcheck.dll

Browser plugins

---------------

AcroIEHelperShim Library C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

Adobe Acrobat C:\Program Files\Internet Explorer\plugins\nppdf32.dll

BitDefender QuickScan C:\WINDOWS\Downloaded Program Files\qsax.dll

Java Platform SE 6 U22 c:\program files\java\jre6\bin\jp2ssv.dll

Java Platform SE 6 U22 C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll

Java Platform SE 6 U22 C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

Messenger C:\Program Files\Messenger\msmsgs.exe

Microsoft Money C:\Program Files\Microsoft Money\System\mnyside.dll

Microsoft® Windows® Operating System C:\WINDOWS\system32\mswsock.dll

Microsoft® Windows® Operating System C:\WINDOWS\System32\winrnr.dll

NPSWF32.dll C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll

Windows Presentation Foundation C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

Windows® Internet Explorer C:\WINDOWS\system32\ieframe.dll

(verified) Microsoft® Windows® Operating System C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

Scan

----

MD5: c15af9be34b584741a95c46e5125e499 C:\Program Files\ADS\WebLinkActiveX\adsService.dll

MD5: a9a5cdfda52257db4488f457c3f4022a C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe

MD5: 6b11c9deebb5f73b29b7721fb842a3a4 C:\Program Files\APC\APC PowerChute Personal Edition\drvutil.dll

MD5: dc45ab27932447b598848b10650313c5 C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe

MD5: 31124eb564001ca25d6672941dc48f50 C:\Program Files\APC\APC PowerChute Personal Edition\pdcdll.dll

MD5: 2997f006d3d19185c31d1491f44c432c C:\Program Files\APC\APC PowerChute Personal Edition\res.dll

MD5: 9e32b111edf9d7fb2d420730288cec58 C:\Program Files\APC\APC PowerChute Personal Edition\UpsControl.dll

MD5: 36d1fd35b6cd118d9ad3e6c1298ee2b6 C:\Program Files\APC\APC PowerChute Personal Edition\UpsDevice.dll

MD5: 3cdea45c32aa24f161c55fa4b33cc063 C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

MD5: f31208835709a62ecc5d45211d89c772 C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

MD5: 79f4ae25569b91ac5acc77bf24f93c6d C:\Program Files\Common Files\Intuit\DataProtect\QBIDPService.exe

MD5: 65e4bfc416f58b68d09bf2001c656679 C:\Program Files\Common Files\Intuit\Entitlement Client\v6.0\Client\EntitlementClientBootstrap.dll

MD5: 7cf6df652041e4abd07a0c1ae4b34c71 C:\Program Files\Common Files\Intuit\QuickBooks\addinmgr2.dll

MD5: e3d38b161df831fabbbf46ed81225a7a C:\Program Files\Common Files\Intuit\QuickBooks\CFScan.dll

MD5: 7badeb5db517b1a93c328adee5cb7eae C:\Program Files\Common Files\Intuit\QuickBooks\CoLocator2.dll

MD5: 6bee1814470dc12fa20c53dfc3c97ebb C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe

MD5: e842ca86ec7053d803456cb01d4c35c9 C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe

MD5: 0ae26750724a178dfcce554ae9255284 C:\Program Files\Common Files\Intuit\QuickBooks\QBDBPortFinder.dll

MD5: c66f38721f6465934a4d781836b64cd4 C:\Program Files\Common Files\Intuit\QuickBooks\QBInstanceFinder.dll

MD5: a46184ee6ffb9c386a28576a290e74be C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\QBMsgMgrps.dll

MD5: 2e4d0810d8d3e74bf9420d094cfa0fb1 C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\QBMsgRequestMgr.dll

MD5: b1e6009087903062a4aad53bcbf28939 C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\QBUChannel.dll

MD5: df2f749cf40f6b766c85db6cd15c211f C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\QBUServiceMgr.dll

MD5: fc2741a70b84d7e7ba5f51a352669ee8 C:\Program Files\Common Files\Intuit\QuickBooks\stlport_r50.dll

MD5: 8ee77a87d72bd9f9bbf6d1741cd79eeb C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS

MD5: 07aa10f524d57cd6df42e501f0c9d6f1 C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe

MD5: a9d7153b413dd0a43aac72190473eeaf C:\Program Files\Internet Explorer\ieproxy.dll

MD5: 0bf28e777209ef48ad215c809ad2cbb5 C:\Program Files\Internet Explorer\plugins\nppdf32.dll

MD5: 5dd552e15419354fcd8ee92ae2660814 C:\Program Files\Internet Explorer\xpshims.dll

MD5: 1ec80973efa8ffb7fd50a3ce4ba4eca2 C:\Program Files\Intuit\QuickBooks 2011\abmapi.dll

MD5: 31af59b34e4466ee096bc70bfb32b764 C:\Program Files\Intuit\QuickBooks 2011\Accountant.dll

MD5: bd8a9cbbd8fae803862f7033e6a05eb0 C:\Program Files\Intuit\QuickBooks 2011\ACE.dll

MD5: d9a587da8549e665e0b072ba2998af0c C:\Program Files\Intuit\QuickBooks 2011\ACM.dll

MD5: 1991abbee53d4c0ee9806b4f630987b6 C:\Program Files\Intuit\QuickBooks 2011\ADR.dll

MD5: 5bc8b222ac9377b47a3b2b9299ca288f C:\Program Files\Intuit\QuickBooks 2011\APPCORE.dll

MD5: b0438145bdb35893d2d743cc18b9fe82 C:\Program Files\Intuit\QuickBooks 2011\BackupLib.dll

MD5: dc3e0fbfbd8b9b826806875ca8f6b90b C:\Program Files\Intuit\QuickBooks 2011\bizutil.dll

MD5: 9c1ec37fc1c7f66c83ce2bc55c9f358b C:\Program Files\Intuit\QuickBooks 2011\boost_regex-vc90-mt-p-1_33.dll

MD5: e0e31b370e3ca32e508cbee6b7ec6e6c C:\Program Files\Intuit\QuickBooks 2011\boost_serialization-vc90-mt-p-1_33.dll

MD5: 8834288f813ec643b9f58d7de7e6a976 C:\Program Files\Intuit\QuickBooks 2011\cindexdb.dll

MD5: fdcc19a1d2b1229695c62f3af039ff12 C:\Program Files\Intuit\QuickBooks 2011\DatabaseManager.dll

MD5: f5dd097058c147cde4c5aa476b2f3f2c C:\Program Files\Intuit\QuickBooks 2011\dbghelp.dll

MD5: 7f83f3380b0265eced742387697e6181 C:\Program Files\Intuit\QuickBooks 2011\dbicu11.dll

MD5: dfe34774a89f456a99d386b14ad68e41 C:\Program Files\Intuit\QuickBooks 2011\dbicudt11.dll

MD5: ea5fb736f9437a99f39d9aa53498f5be C:\Program Files\Intuit\QuickBooks 2011\dblgen11.dll

MD5: e0ade91c23e5402e70d5d1a8fd3ffdd2 C:\Program Files\Intuit\QuickBooks 2011\dblib11.dll

MD5: 5f4cebf8febb68378b58369f3774dfbc C:\Program Files\Intuit\QuickBooks 2011\dbtool11.dll

MD5: a5c857fac79ad5d1e97044dc53cbc1f7 C:\Program Files\Intuit\QuickBooks 2011\DMAccountant.dll

MD5: 0cc15fb903b34296547931900c3e2e6e C:\Program Files\Intuit\QuickBooks 2011\DMALIAS.dll

MD5: ee6d197a49987e50cb4aa139ed7f1d48 C:\Program Files\Intuit\QuickBooks 2011\DMAUDIT.dll

MD5: cf765e25f3fc2b5991cec23ef2aa548b C:\Program Files\Intuit\QuickBooks 2011\DMBUDGET.dll

MD5: 778a5f3aabccdb8e1af48d1ba95e31fa C:\Program Files\Intuit\QuickBooks 2011\DMCore.dll

MD5: 793338cf18ba8c79947f109dfc288fd0 C:\Program Files\Intuit\QuickBooks 2011\DMDATASYNC.dll

MD5: 759bfbc9499d1a823e5c862c05ebf96c C:\Program Files\Intuit\QuickBooks 2011\DMDQE.dll

MD5: 3019f925f41a6780d9b00db3cfc6c6db C:\Program Files\Intuit\QuickBooks 2011\DMEDL.dll

MD5: d38f9895bfcd49ed3b5e3102586e0475 C:\Program Files\Intuit\QuickBooks 2011\DMGenPrefs.dll

MD5: e5a998946725d754569859de9c08b3d4 C:\Program Files\Intuit\QuickBooks 2011\DMInventory.dll

MD5: 5d155388cc8befee67ac8dc0a72553ad C:\Program Files\Intuit\QuickBooks 2011\DMOLB.dll

MD5: 845cce1f10d111cea28abd6b87aeb15c C:\Program Files\Intuit\QuickBooks 2011\DMPAYROLL.dll

MD5: 06c878a44033def0a307f190c42b1324 C:\Program Files\Intuit\QuickBooks 2011\DMPREFS.dll

MD5: 250f732384bf617e7abd420346f159a1 C:\Program Files\Intuit\QuickBooks 2011\DMTIME.dll

MD5: 99f83e38489a3d011f07e6f729a1a68c C:\Program Files\Intuit\QuickBooks 2011\DMTXN.dll

MD5: 4980daabd74deb12b5c5ad12047d9d7c C:\Program Files\Intuit\QuickBooks 2011\DMUI.dll

MD5: 1f8815dc6672f559de83648ed8e904c8 C:\Program Files\Intuit\QuickBooks 2011\DMUSERS.dll

MD5: 9f360d46e5a460926f1adaefd2241e12 C:\Program Files\Intuit\QuickBooks 2011\DocumentManagement.dll

MD5: a51bc34a754aba2440a67dfdb0f2c90a C:\Program Files\Intuit\QuickBooks 2011\ELCORE.dll

MD5: 405c1b34a2f7e178dfb6b164a86cfd22 C:\Program Files\Intuit\QuickBooks 2011\ESHELL.dll

MD5: 2f553861da52bf58a3e4b246b67c4f19 C:\Program Files\Intuit\QuickBooks 2011\FeatureMgr.dll

MD5: 579e42321c5c48366cb33f7acedd71b5 C:\Program Files\Intuit\QuickBooks 2011\Features.dll

MD5: 028df8e73f622502b9dd87ff9ddcb251 C:\Program Files\Intuit\QuickBooks 2011\FileManifest.dll

MD5: 6393038e358d6cd04a510ead43e85c94 C:\Program Files\Intuit\QuickBooks 2011\IdentityMine.Windows.dll

MD5: 520ce25901b9c561a4f50a1ad9d9df99 C:\Program Files\Intuit\QuickBooks 2011\IdentityMine.Windows.Media3D.dll

MD5: ce3a70030bc77cc896f77040d74771ba C:\Program Files\Intuit\QuickBooks 2011\IdentityMine.Windows.Panels.dll

MD5: 33d29592c0f1cdcace9c6a8b0a751512 C:\Program Files\Intuit\QuickBooks 2011\mbpopup.dll

MD5: 49f874690f504d2f11f6ff93c6bb483c C:\Program Files\Intuit\QuickBooks 2011\msgDBAddIn.dll

MD5: 685058ef8d9d087ad8f25786b0022301 C:\Program Files\Intuit\QuickBooks 2011\NAAuthTool.dll

MD5: cb658dc70e5baf9b540a63f7e4324777 C:\Program Files\Intuit\QuickBooks 2011\OPAQUEBUFFER.dll

MD5: 7badd7546387770c36d2b3a4a246ac68 C:\Program Files\Intuit\QuickBooks 2011\paycore.dll

MD5: 8d491e52a6d8e3ce37648b919ebec74e C:\Program Files\Intuit\QuickBooks 2011\PAYRES.dll

MD5: e3d8ab08132b0ac012ab6ca316ac848c C:\Program Files\Intuit\QuickBooks 2011\PAYSERV.dll

MD5: 4300b78e3b9405101df13a5205d69ef8 C:\Program Files\Intuit\QuickBooks 2011\PAYUTIL.dll

MD5: d1e6a8e6d46bbdbbba525b030245b719 C:\Program Files\Intuit\QuickBooks 2011\payxsgen.dll

MD5: 32259e1c334d6778f74bab781b3d5b67 C:\Program Files\Intuit\QuickBooks 2011\PM.dll

MD5: 46eccb5624f44f7c4bf1b1f0c0a651c0 C:\Program Files\Intuit\QuickBooks 2011\PortFile.dll

MD5: a75072852b6096678c962937ff1a7cf2 C:\Program Files\Intuit\QuickBooks 2011\PREFS.dll

MD5: 94dba37e4ea7d428dcfb6b04dcb7ce0b C:\Program Files\Intuit\QuickBooks 2011\PRNotificationLoader.dll

MD5: 2a2e9e562bf7a1b794657fcd4b835db0 C:\Program Files\Intuit\QuickBooks 2011\QB2WPFBridge.dll

MD5: 059110b62a8a6eb62e07aa180ae6bdad C:\Program Files\Intuit\QuickBooks 2011\QBATTR32.dll

MD5: ead321cdff68182077dc53c22d03d225 C:\Program Files\Intuit\QuickBooks 2011\qbbrow32.dll

MD5: 292007d8c732d141058c0a17f40fb5f3 C:\Program Files\Intuit\QuickBooks 2011\QBCHAO32.dll

MD5: 114955994ff71567e86ed4960fb06ee3 C:\Program Files\Intuit\QuickBooks 2011\qbci32.dll

MD5: 384ac07d087f6795af9460df1c0fa982 C:\Program Files\Intuit\QuickBooks 2011\QBCompressor.dll

MD5: ab6ee66c96504b48cba43c5cb18af3de C:\Program Files\Intuit\QuickBooks 2011\QBCONV32.dll

MD5: 87d6e8fd030a6ad861d821b9e2ecebef C:\Program Files\Intuit\QuickBooks 2011\QBDomain.dll

MD5: 9ed8a83548ce2b8936a846c5e9c9ae32 C:\Program Files\Intuit\QuickBooks 2011\qbform32.dll

MD5: e5410fdd31608b3efd8a04ee0cfa2294 C:\Program Files\Intuit\QuickBooks 2011\QBInbox.dll

MD5: 6bb8d5bdbdb68e5f2bd19bf13e3c6cba C:\Program Files\Intuit\QuickBooks 2011\QBINTR32.dll

MD5: aaf35624636ebc973ec311570827934c C:\Program Files\Intuit\QuickBooks 2011\QBITools.dll

MD5: 4eeb1c33d833418d3e8e9a4ea55fc4a8 C:\Program Files\Intuit\QuickBooks 2011\qblist32.dll

MD5: 225f9b9ba87be1bcaadb3853c283e740 C:\Program Files\Intuit\QuickBooks 2011\QBMAPILibrary.dll

MD5: da36e3b951b2f7e5eb2d527064d65948 C:\Program Files\Intuit\QuickBooks 2011\QBMAS32.dll

MD5: 4aa080b0e8eccbca40a6bbf036aa662c C:\Program Files\Intuit\QuickBooks 2011\QBMFCT32.dll

MD5: 0ba31aa55df98ae9c98b96eb9c89a8b6 C:\Program Files\Intuit\QuickBooks 2011\QBMSIntg.DLL

MD5: a1c3eed435a736c4ccbd47b21b8f0787 C:\Program Files\Intuit\QuickBooks 2011\QBOESD32.dll

MD5: e9127ead5211e7e2ea00de730a624517 C:\Program Files\Intuit\QuickBooks 2011\QBONLI32.dll

MD5: f952ab3831cd9459ad710e9105a45aa4 C:\Program Files\Intuit\QuickBooks 2011\qbot.dll

MD5: 7f9e5daf5d699305e86adb2801f025f1 C:\Program Files\Intuit\QuickBooks 2011\QBQWUT32.DLL

MD5: be112c8245cee17624b1addba0bc35e2 C:\Program Files\Intuit\QuickBooks 2011\QBSDKNotify.dll

MD5: b17c95467f319837ac5f1033b171e99d C:\Program Files\Intuit\QuickBooks 2011\QBSendError20.dll

MD5: 06a5865497066375702aa25b2dd7c545 C:\Program Files\Intuit\QuickBooks 2011\QBSTYL32.dll

MD5: 8a1f7be97099d8e3045a3cbfe41b8d1c C:\Program Files\Intuit\QuickBooks 2011\qbtool32.dll

MD5: 9c1c6e0d2cb77703d4d59b07fde200ce C:\Program Files\Intuit\QuickBooks 2011\qbtxn32.dll

MD5: 73f51866bcc161ca896fc947884b0ec5 C:\Program Files\Intuit\QuickBooks 2011\QBUtilities.dll

MD5: b1c70e2c9efdb32624cc70ab91bada17 C:\Program Files\Intuit\QuickBooks 2011\QBW32.EXE

MD5: f15b2c01a7046c3c41333d218496d8b7 C:\Program Files\Intuit\QuickBooks 2011\qbwfls32.dll

MD5: 7f0494e324a8197235e50c3e4f998098 C:\Program Files\Intuit\QuickBooks 2011\QBWIN32.dll

MD5: 15b90d0c45ef72dde5b0e274c506aa5f C:\Program Files\Intuit\QuickBooks 2011\QBWMain.dll

MD5: a7d5304afbc71ef73cbd9a57d7f0a985 C:\Program Files\Intuit\QuickBooks 2011\qbwpsrun.dll

MD5: 04823be11a6855cc13ffced5db25e1e1 C:\Program Files\Intuit\QuickBooks 2011\QBWRPT32.dll

MD5: 3c8c063e407c8417068d3b5d9f811375 C:\Program Files\Intuit\QuickBooks 2011\qbxladin.dll

MD5: 24fa6c2139a673ec56f1a0478334071e C:\Program Files\Intuit\QuickBooks 2011\ReportBridge.dll

MD5: 0bda2a1d46ffc98f7c2fe79d815aedda C:\Program Files\Intuit\QuickBooks 2011\ReportCenter.dll

MD5: 626b8676babe425d2b1bc3e69fcf4561 C:\Program Files\Intuit\QuickBooks 2011\ReportInterop.dll

MD5: 6216afcd0dbec0ca1b81d84b4608a7cd C:\Program Files\Intuit\QuickBooks 2011\sdkutil.dll

MD5: 083f47b23d047a4e273dd2fe1139f36f C:\Program Files\Intuit\QuickBooks 2011\skucore.dll

MD5: 04b46e0fe8547955369daecdcc91579a C:\Program Files\Intuit\QuickBooks 2011\SSCE5232.dll

MD5: fc2741a70b84d7e7ba5f51a352669ee8 C:\Program Files\Intuit\QuickBooks 2011\stlport_r50.dll

MD5: 312d8e767145a5fa9160d89f60ca4d06 C:\Program Files\Intuit\QuickBooks 2011\TEJ32.dll

MD5: 9be063092f4bd629c48e3ada3876ca55 C:\Program Files\Intuit\QuickBooks 2011\TRACKING.dll

MD5: 51e11ebe9c18eea89e559d0eab402366 C:\Program Files\Intuit\QuickBooks 2011\txncore.dll

MD5: 7fc54d40ab93aa082f20f1a73d014bbd C:\Program Files\Intuit\QuickBooks 2011\TXNFORM.dll

MD5: 16062d627d4b2645933105c5b6a06efd C:\Program Files\Intuit\QuickBooks 2011\ui.dll

MD5: 5ba87369615a4c1acb491bb31518b28f C:\Program Files\Intuit\QuickBooks 2011\UM.dll

MD5: 195ed09e0b4f3b09ea4a3b67a0d3f396 C:\Program Files\Intuit\QuickBooks 2011\WPFToolkit.dll

MD5: 3f59ede1444c14cfbaa15c7ebbfe6196 c:\program files\java\jre6\bin\jp2ssv.dll

MD5: 9ae07549a0d691a103faf8946554bdb7 C:\Program Files\Java\jre6\bin\jqs.exe

MD5: 3ed8e561044723c6039a8a20a3ae60cc C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll

MD5: bee32bce0d0a5bf5692d9020bd0c0636 C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

MD5: cbb665b57beed7583fe58b55daa05932 C:\Program Files\Malwarebytes' Anti-Malware\mbam.dll

MD5: 33bfce71f407f24e5dfdb7dd46ce2d6d C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe

MD5: d2fd9a8bc952f09be3d29544a546897a C:\Program Files\Malwarebytes' Anti-Malware\mbamnet.dll

MD5: 37036c07983ef1024b2ff3c28aae5700 C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

MD5: 3e930c641079443d4de036167a69caa2 C:\Program Files\Messenger\msmsgs.exe

MD5: a648df5030c2cc9552cfdf5195ab196d C:\Program Files\Microsoft Money\System\misstub.dll

MD5: d91c44aa02f4e577414ee667edb2e1d8 C:\Program Files\Microsoft Money\System\mnyside.dll

MD5: 310c15fd8358b2c4cd7a5b98a112883f C:\WINDOWS\AppPatch\AcGenral.DLL

MD5: 17b9d4728cfcee1650f900e8edbd6686 C:\WINDOWS\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll

MD5: 617fb85504f7be3d0231b5c67724b1ba C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\0309936a8e1672d39b9cf14463ce69f9\mscorlib.ni.dll

MD5: f798be75656b0ccbc9e642b103b03385 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationCore\caafa254739e326b0cf55eed815b4333\PresentationCore.ni.dll

MD5: 9ffa9fb2b9470dbd346524cea1c06d61 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\e9bb32c656a2f80b629f129d738c392b\PresentationFontCache.ni.exe

MD5: 0b7d21c02412be904d77273707d75598 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\6cf82f370413a2cd1e6bc54060334753\PresentationFramework.Luna.ni.dll

MD5: 4f2ce541c289069d4c77d6982ca47d60 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\999df2b262da53356dda514512bb7bb8\PresentationFramework.ni.dll

MD5: 2184bc69d6d495b62f349724c6859d87 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\e468e9265c844f74577530e4df71f120\PresentationFramework.Aero.ni.dll

MD5: 95cc5507d647f97e4329511a3160e1c6 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Core\bd2e04dfab2993479ae17ea3fa4f6222\System.Core.ni.dll

MD5: 43fbf126d8efe9cb2bca5fb1e365d832 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\0f3d321ebd65af974ff0ad424223276d\System.ServiceProcess.ni.dll

MD5: f4e1f9d3b2762bba015ba723792f51f4 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\f6a9a002526806f3a5b745cf5c407cae\System.ni.dll

MD5: f3ecee32b5d0594e755b9ac81b762b42 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\1492e9393417d6e91b5ddc746b5ef320\UIAutomationProvider.ni.dll

MD5: 0f262aa8a99114fc33f0de8aa6fd95b4 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\WindowsBase\11526c1635b97a7d49e25e72ed6e9662\WindowsBase.ni.dll

MD5: 823451876778f382b23afe20ef2ddc20 C:\WINDOWS\Downloaded Program Files\qsax.dll

MD5: ea3af33a9341b88d23fdc20d6ec826fe C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\fusion.dll

MD5: 2bac92e8ac5e16ed60062e9141b8d5f6 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll

MD5: f282d4edd85d53e20d902cc92190c5f5 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsec.dll

MD5: 429e3efafcae6c89a57cd5d8e3442cae C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll

MD5: ab87eeffd18f2baafc274e7075ea6c67 C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

MD5: 93afb83fbc1f9443cac722fca63d73bf C:\WINDOWS\system32\comctl32.dll

MD5: ed0c0df222209e43ad9afbf3fe87dde0 C:\WINDOWS\system32\comsvcs.dll

MD5: 8fcf03e4d7be9b5587ccf11719959006 C:\WINDOWS\system32\corpol.dll

MD5: bdaaf79dd63f194434d31a74b9bb8b77 C:\WINDOWS\system32\CRYPT32.dll

MD5: c14350fc0d47d806699c4f907fc6785b C:\WINDOWS\system32\cryptnet.dll

MD5: 515a7fae2070c2b0242b2353443e2f11 C:\WINDOWS\system32\cscdll.dll

MD5: 2a9e427681169f02274ad8c17d52fa2d C:\WINDOWS\system32\CSRSRV.dll

MD5: 0607cbc6fa20114cb491efe4b2f9efad C:\WINDOWS\system32\d3d9.dll

MD5: 56adb11f7d4d0816c0be1e701c1b5e52 C:\WINDOWS\system32\D3DIM700.DLL

MD5: e2092f0a1d7abc243f9c2362483d150d C:\WINDOWS\System32\dimsntfy.dll

MD5: 389496118b3b03c2328024af320132ac C:\WINDOWS\system32\DNSAPI.dll

MD5: 5f7e24fa9eab896051ffb87f840730d2 c:\windows\system32\dnsrslvr.dll

MD5: 355556d9e580915118cd7ef736653a89 C:\WINDOWS\System32\drivers\afd.sys

MD5: fe9cb643a034285031502d3369e5a869 C:\WINDOWS\System32\DRIVERS\e100b325.sys

MD5: aae37f0f2f613218dce17b42a18c38db C:\WINDOWS\system32\drivers\ftdibus.sys

MD5: 48bfd1ba45c9c9e7ab339e25abfba1d2 C:\WINDOWS\system32\drivers\ftser2k.sys

MD5: 748031ff4fe45ccc47546294905feab8 C:\WINDOWS\System32\DRIVERS\HidBatt.sys

MD5: 8854f5453cce4c5831538e935f92f73b C:\WINDOWS\system32\drivers\ialmkchw.sys

MD5: 3046f83c8a6acebb9eaa834c2cd7105c C:\WINDOWS\System32\DRIVERS\ialmnt5.sys

MD5: f0890825e7a9f4a808190a781c480568 C:\WINDOWS\system32\drivers\ialmsbw.sys

MD5: eca00eed9ab95489007b0ef84c7149de C:\WINDOWS\system32\drivers\mbam.sys

MD5: 0dc719e9b15e902346e87e9dcd5751fa C:\WINDOWS\System32\DRIVERS\mrxsmb.sys

MD5: 419f4d80fe7e34e2626c84b3c6035955 C:\WINDOWS\system32\drivers\NMSCFG.SYS

MD5: b911c822922cf62df83ad36d5c9775cc C:\WINDOWS\system32\drivers\smwdm.sys

MD5: 47ddfc2f003f7f9f0592c6874962a2e7 C:\WINDOWS\System32\DRIVERS\srv.sys

MD5: f5b754cdea20bbb3a31e16a776ede6d6 C:\WINDOWS\system32\ESENT.dll

MD5: e3eae647947b8d0214f8e89dab1b496e C:\WINDOWS\system32\hpzlnt07.dll

MD5: af61826b82de7b95d5db8ee075a172d2 C:\WINDOWS\system32\ieframe.dll

MD5: c0b6195f1afda4a3061915501eb75d4a C:\WINDOWS\system32\iepeers.dll

MD5: ba356bd33397936d2e292cb00f80c164 C:\WINDOWS\system32\iertutil.dll

MD5: 1c9da804c601d6c1270bf9658fdc4a86 C:\WINDOWS\system32\igfxsrvc.dll

MD5: a77f650fe3c5ac3b5d26dbd86d7e18e0 C:\WINDOWS\system32\InetClnt.dll

MD5: 77ae096874bb2d5d551d2ba7f7a5e2df C:\WINDOWS\system32\javacypt.dll

MD5: 0689622e6484934eb6e5f4d3a96311f9 C:\WINDOWS\system32\jscript.dll

MD5: a525c96c51d55111fdf3bea9ffffc7ae C:\WINDOWS\system32\kerberos.dll

MD5: 20fa028cb6506591a99c51432a3c0174 C:\WINDOWS\system32\LangWrbk.dll

MD5: 9fad7dff67555ff1e06bc4a3893024a7 C:\WINDOWS\System32\logon.scr

MD5: bd31dc6dbe9333c4fbd4bdf0899f2160 C:\WINDOWS\system32\LSASRV.dll

MD5: 5aace82bcdb40634290930f93be745b7 C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll

MD5: 14da23d2b9310c694aba9dcae14dc059 C:\WINDOWS\system32\msfeeds.dll

MD5: 22ba5235ea846eda87f68a1dcc2bfcf9 C:\WINDOWS\system32\mshtml.dll

MD5: d3f72d50de53f9f1f55240115af4d42e C:\WINDOWS\system32\msi.dll

MD5: 65e6742fe0dd8319b1acf820caf63044 C:\WINDOWS\system32\msjava.dll

MD5: c7e39ea41233e9f5b86c8da3a9f1e4a8 C:\WINDOWS\system32\mspmsnsv.dll

MD5: 64b33cc5bf131def2721394cf9b3f8ed C:\WINDOWS\system32\MSVBVM60.DLL

MD5: 585992d78b671aaa075c02241309795d C:\WINDOWS\system32\MSVCIRT.dll

MD5: 943337d786a56729263071623bbb9de5 C:\WINDOWS\system32\mswsock.dll

MD5: 062f837c1fbdb6a0a75f82efc2ee8e74 C:\WINDOWS\system32\netshell.dll

MD5: eeea4a259891d43fec7c25e45973740d C:\WINDOWS\system32\NMSSvc.Exe

MD5: f8f0d25ca553e39dde485d8fc7fcce89 C:\WINDOWS\system32\ntdll.dll

MD5: 40b0f98bad16ad5def894e88c3ef8014 C:\WINDOWS\system32\ODBC32.dll

MD5: 2c288aa87e4723ac9ff4d76a192ec3f8 C:\WINDOWS\system32\odbccp32.dll

MD5: 7a6a7900b5e322763430ba6fd9a31224 C:\WINDOWS\system32\ole32.dll

MD5: 1b2be5777f69a71778f52ffee1c798d6 C:\WINDOWS\system32\OLEAUT32.dll

MD5: 77de1f81666a4766bfed712dc7232f4e C:\WINDOWS\system32\PresentationNative_v0300.dll

MD5: d4502f124289a31976130cccb014c9aa C:\WINDOWS\system32\RPCRT4.dll

MD5: abeedd547e939ad827b2e29dec754206 C:\WINDOWS\system32\schannel.dll

MD5: e86423aa9aa8c382af02b94a058dc2aa C:\WINDOWS\system32\SHELL32.dll

MD5: 99bc0b50f511924348be19c7c7313bbf C:\WINDOWS\system32\SHSVCS.dll

MD5: 60784f891563fb1b767f70117fc2428f C:\WINDOWS\system32\spoolsv.exe

MD5: 3a7c3cbe5d96b8ae96ce81f0b22fb527 c:\windows\system32\srvsvc.dll

MD5: 78bb1e601edab917094b0260a5a57c85 C:\WINDOWS\system32\urlmon.dll

MD5: a93aee1928a9d7ce3e16d24ec7380f89 c:\windows\system32\userinit.exe

MD5: 9e03dc5ab51cfd0190541ce2038d819d C:\WINDOWS\system32\USP10.dll

MD5: b62bb2be4227edbb1091cc7c7076fd30 C:\WINDOWS\system32\VMHELPER.DLL

MD5: cc951c2212a200475a587a440e0aa804 C:\WINDOWS\system32\WININET.dll

MD5: d72b9ec3337b247a666f098f3d6b43de C:\WINDOWS\System32\winrnr.dll

MD5: ec0a223c4854e98a3afb2c31b7b420a0 C:\WINDOWS\system32\winsrv.dll

MD5: 2cc34e8bb667eef78899546e12649196 C:\WINDOWS\system32\WlNotify.dll

MD5: f92e1076c42fcd6db3d72d8cfe9816d5 C:\WINDOWS\system32\wscntfy.exe

MD5: 16403217ab6fc5c30c14c6b12098ad4b C:\WINDOWS\System32\xpsp2res.dll

MD5: 67bdb40fbe6cecc320507161b58d134a C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcm90.dll

MD5: 95decd7ee37e740f4176baf60897a92f C:\WINDOWS\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfc90.dll

MD5: 736b12b725aeb2b07f0241a9f680cb10 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll

MD5: 33d9b7bb7ba323bafe489df033dac824 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6002.22509_x-ww_c7dad023\gdiplus.dll

No file uploaded.

Scan finished - communication took 2 sec

Total traffic - 0.02 MB sent, 0.51 KB recvd

Scanned 621 files and modules - 45 seconds

==============================================================================

and....

C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\mrxsmb.sys.vir a variant of Win32/Rootkit.Kryptik.DM trojan

C:\System Volume Information\_restore{95E89D1A-534E-4289-B0B7-EAB3CDDE4476}\RP106\A0014108.sys a variant of Win32/Rootkit.Kryptik.DM trojan

C:\System Volume Information\_restore{95E89D1A-534E-4289-B0B7-EAB3CDDE4476}\RP107\A0015108.sys a variant of Win32/Rootkit.Kryptik.DM trojan

C:\System Volume Information\_restore{95E89D1A-534E-4289-B0B7-EAB3CDDE4476}\RP107\A0015122.sys a variant of Win32/Rootkit.Kryptik.DM trojan

C:\System Volume Information\_restore{95E89D1A-534E-4289-B0B7-EAB3CDDE4476}\RP107\A0016122.sys a variant of Win32/Rootkit.Kryptik.DM trojan

C:\System Volume Information\_restore{95E89D1A-534E-4289-B0B7-EAB3CDDE4476}\RP108\A0016129.sys a variant of Win32/Rootkit.Kryptik.DM trojan

C:\System Volume Information\_restore{95E89D1A-534E-4289-B0B7-EAB3CDDE4476}\RP108\A0016158.sys a variant of Win32/Rootkit.Kryptik.DM trojan

C:\System Volume Information\_restore{95E89D1A-534E-4289-B0B7-EAB3CDDE4476}\RP108\A0016164.sys a variant of Win32/Rootkit.Kryptik.DM trojan

C:\System Volume Information\_restore{95E89D1A-534E-4289-B0B7-EAB3CDDE4476}\RP109\A0017598.sys a variant of Win32/Rootkit.Kryptik.DM trojan

C:\WINDOWS\maxdrive\mrxsmb.sys a variant of Win32/Rootkit.Kryptik.DM trojan

E:\sext2sp.chm multiple threats

E:\Documents and Settings\All Users\Application Data\ReviverSoft\Registry Reviver\InstallCache\{5537676F-A3FF-4D7E-8089-9434492F4104}\Registry Reviver.msi a variant of Win32/SlowPCfighter application

Link to post
Share on other sites

Please Launch Malwarebytes' Anti-Malware.

  • Please click Check for Updates to see if any updates are found. If so, please allow MBAM to download and install them.
  • Once the program has loaded, select Perform full scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a location you will remember.
  • Copy and Paste that log into your next reply.

Note:

If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.

Click OK for either of the prompts and let MBAM proceed with the disinfection process.

If asked to restart the computer, please do so immediately.

NOTE: you may need to reinstall Malwarebytes, as the virus you just had may have corrupted it ;)

Link to post
Share on other sites

Malwarebytes' Anti-Malware 1.51.1.1800

www.malwarebytes.org

Database version: 7355

Windows 5.1.2600 Service Pack 3

Internet Explorer 8.0.6001.18702

8/2/2011 11:05:34 AM

mbam-log-2011-08-02 (11-05-34).txt

Scan type: Full scan (C:\|E:\|)

Objects scanned: 285129

Time elapsed: 2 hour(s), 0 minute(s), 47 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

(No malicious items detected)

Link to post
Share on other sites

Your logs appear to be clean :)!

Let's see what programs of yours need updating ;):

Please download Security Check by screen317 from here or here.

  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

Link to post
Share on other sites

Results of screen317's Security Check version 0.99.18

Windows XP Service Pack 3

Internet Explorer 8

``````````````````````````````

Antivirus/Firewall Check:

Windows Firewall Enabled!

ESET Online Scanner v3

WMI entry may not exist for antivirus; attempting automatic update.

```````````````````````````````

Anti-malware/Other Utilities Check:

Malwarebytes' Anti-Malware

Java 6 Update 22

Out of date Java installed!

Adobe Flash Player 10.3.181.14

Adobe Reader X (10.0.1) Adobe Reader Out of Date!

Mozilla Firefox (x86 en-US..)

````````````````````````````````

Process Check:

objlist.exe by Laurent

Malwarebytes' Anti-Malware mbamservice.exe

Malwarebytes' Anti-Malware mbamgui.exe

``````````End of Log````````````

Link to post
Share on other sites

Your logs appear to be clean ;)

Before we move on, please take the time to install the following updates, as using outdated applications leaves you extremely vulnerable to getting infected again ;):

You're using an old version of Adobe Acrobat Reader, this can leave your PC open to vulnerabilities, you can update it here (uninstall version 7.0 first):

Adobe Reader X

Note: I suggest you uncheck an optional, third-party download (eg. McAfee Security Scan Plus).

After successfully installing Adobe Reader X, see this article on how to make this program more secure: Adobe Reader X secures itself by playing in the sandbox.

-----------

Java is out of date and older versions contain vulnerabilities. Please update to the newest version.

Download the newest version from here http://www.oracle.com/technetwork/java/javase/downloads/index.html.

It's important to remove older versions of Java since it does not do so automatically and old versions still leave you vulnerable.

Go to Start > Control Panel and open Add or Remove Programs.

Search in the list for all previous installed versions of Java. (J2SE Runtime Environment).

They will have this icon next to them: javaicon.gif

Select each in turn and click Remove.

Once old versions are gone, please install the newest version.

-----------

Please let me know how the updates went, as failed updates may indicate additional malware ;)

Link to post
Share on other sites

Glad to hear the updates went well :)

Unless there are any further issues, I will now provide you with some suggestions for security software, but first, ComboFix must be uninstalled ;):

The following will implement some cleanup procedures as well as reset System Restore points:

Click Start > Run and copy/paste the following bolded text into the Run box and click OK:

ComboFix /Uninstall

-------------

Please consider using these ideas to help secure your computer. While there is no way to guarantee safety when you use a computer, these steps will make it much less likely that you will need to endure another infection. While we really like to help people, we would rather help you protect yourself so that you won't need that help in the future. :)

Please either enable Automatic Updates under Start -> Control Panel -> Automatic Updates or get into the habit of checking Windows Update regularly. They usually have security updates every month. You can set Windows to notify you of Updates so that you can choose, but only do this if you believe you are able to understand which ones are needed. This is a crucial security measure.

It is really dangerous to go online without an antivirus. Without one, you are extremely likely to get infected and the consequences could be even worse next time. All of the following are excellent free antiviruses. Be sure to only install one.

avast!.

AntiVir

AVG

Please consider installing and running some of the following programs; they are either free or have free versions of commercial programs:

Spybot-Search & Destroy

A tutorial on using Spybot to remove spyware from your computer may be found here. Please also remember to enable Spybot's "Immunize" and "TeaTimer" features if you don't have the resident part of another anti-spyware program running.

SpywareBlaster

A tutorial on using SpywareBlaster to prevent malware from ever installing on your computer may be found here.

SpywareGuard

A tutorial on using SpywareGuard for real-time protection against spyware and hijackers may be found here.

Please, consider maintaining a firewall with HIPS (Host Intrusion Prevention Systems). Firewalls are extremely important and are the first part of your computer's defense. HIPS stops malware by monitoring its behavior and it's very important, too.

A firewall is a software program or piece of hardware that helps screen out hackers, viruses, and worms that try to reach your computer over the Internet.

If you are using the Windows Firewall please note that it doesn't monitor or block outbound traffic and is therefore less effective than other free alternatives.

These firewalls are good and do have free versions available

A tutorial on understanding and using firewalls may be found here.

If you use Internet Explorer, it is a good idea to use IE-Spyad for ZonedOut which provides protections against malicious websites. (Requires 2 downloads)

Please keep these programs up-to-date and run them whenever you suspect a problem to prevent malware problems. A number of programs have resident protection and it is a good idea to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and become less effective. That means only one antivirus, firewall and scanning anti-spyware program at a time. Passive protectors, like SpywareBlaster and IE-Spyad can be run with any of them.

Note that there are a lot of rogue programs out there that want to scare you into giving them your money and some malware actually claims to be security programs. If you get a popup for a security program that you did not install yourself, do NOT click on it and ask for help immediately. It is very important to run an antivirus and firewall, but you can't always rely on reviews and ads for information. Ask in a security forum that you trust if you are not sure. If you are unsure and looking for anti-spyware programs, you can find out if it is a rogue here:

http://www.spywarewarrior.com/rogue_anti-spyware.htm

A similar category of programs is now called "scareware." Scareware programs are active infections that will pop-up on your computer and tell you that you are infected. If you look closely, it will usually have a name that looks like it might be legitimate, but it is NOT one of the programs you installed. It tells you to click and install it right away. If you click on any part of it, including the 'X' to close it, you may actually help it infect your computer further. Keeping protection updated and running resident protection can help prevent these infections. If it happens anyway, get offline as quickly as you can. Pull the internet connection cable or shut down the computer if you have to. Contact someone to help by using another computer if possible. These programs are also sometimes called 'rogues', but they are different than the older version of rogues mentioned above.

Please consider using an alternate browser. Mozilla's Firefox browser is a very good alternative. In addition to being generally more secure than Internet Explorer, it has a very good built-in popup blocker and add-ons, like NoScripts, can make it even more secure. Opera is another good option.

If you are interested, Firefox may be downloaded from here

Opera is available here: http://www.opera.com/download/

For much more useful information, please also read Tony Klein's excellent article: How did I get infected in the first place

Hopefully these steps will help to keep you error free. If you run into more difficulty, we will certainly do what we can to help. :)

Link to post
Share on other sites

  • 2 weeks later...
  • Staff

Glad we could help. :)

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.